Claude Code MCP Traffic Hijacked to Steal OAuth Tokens

Claude Code MCP Traffic Hijacked to Steal OAuth Tokens

First seen 8 Jun 2026, 08:16 UTC CybersecuritynewsGbhackersLetsdatascience 91% similarity 68.0

Article Content

Browse articles
ThreatCluster

A new man-in-the-middle (MitM) attack has been identified, targeting Anthropic's Claude Code ecosystem. Threat actors exploit vulnerabilities in the Model Context Protocol (MCP) traffic to intercept OAuth authentication tokens. This attack allows unauthorized access to enterprise SaaS platforms such as Jira, Confluence, and GitHub. Researchers from Mitiga Labs have detailed a five-step attack chain that redirects MCP traffic through attacker-controlled infrastructure. The attack leverages weak protections in the local Claude Code configuration file, specifically ~/.claude.json. As of now, no patch has been released by Anthropic to mitigate this vulnerability. Organizations using Claude Code are at risk of unauthorized access and data breaches. The attack is significant due to the potential for broad access to sensitive enterprise data.

Key Points: • Hackers exploit Claude Code MCP traffic to hijack OAuth tokens. • The attack allows unauthorized access to major SaaS platforms like Jira and GitHub. • No patch has been released by Anthropic to address this vulnerability.

ThreatCluster AI

Timeline

2026-06-08
Mitiga Labs reveals new attack method
Researchers detailed a five-step MitM attack targeting Claude Code's MCP traffic to steal OAuth tokens.
Gbhackers
2026-06-08
Attack method demonstrated
The attack chain was demonstrated by Mitiga Labs, showing how traffic is redirected through attacker-controlled infrastructure.
Cybersecuritynews
2026-06-08
No patch available from Anthropic
As of the latest reports, Anthropic has not released any patches to mitigate the identified vulnerabilities.
Cybersecuritynews

Community

Browse all →